CVE-2026-19379: EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injection
A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the component CGI Endpoint. This manipulation of the argument fname causes os command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19379?
The severity of CVE-2026-19379 is rated as high with a score of 7.3.
How does CVE-2026-19379 allow for exploitation?
CVE-2026-19379 allows for exploitation through OS command injection via the popen function in the /cgi/d.cgi endpoint.
Can CVE-2026-19379 be exploited remotely?
Yes, CVE-2026-19379 can be exploited remotely.
What version of the software is affected by CVE-2026-19379?
The EFM ipTIME AX8004M version 15.09.0 is affected by CVE-2026-19379.
How can I mitigate CVE-2026-19379?
Mitigation of CVE-2026-19379 involves updating to a patched version of the EFM ipTIME AX8004M software that addresses this vulnerability.